ZeroHour

CVE-2026-50349

mass

Local Privilege Escalation via Race Condition in Windows WinSock AFD Driver

CVSS 3.1
7.0 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-50349 is a race condition (CWE-362, also associated with use-after-free, CWE-416) in the Windows Ancillary Function Driver for WinSock (AFD), a kernel driver that provides Winsock socket functionality. A local, authorized (low-privileged) attacker can trigger concurrent operations on a shared resource with improper synchronization, which can lead to exploitable memory corruption in the kernel. Successful exploitation allows the attacker to elevate privileges locally, gaining high-impact access to confidentiality, integrity, and availability on the targeted machine (CVSS 3.1 score of 7.0 High, with local attack vector, high attack complexity, and no user interaction required). Because the AFD driver ships in-box with Windows, all Windows systems running affected builds are potentially exposed; the source data does not specify which Windows versions, so consult Microsoft's advisory for the exact affected range. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days (9th percentile).

What to do: Apply Microsoft's security update addressing CVE-2026-50349 via Windows Update on all Windows endpoints and servers, and confirm affected builds against Microsoft's advisory since version ranges are not specified here. Prioritize systems where untrusted or low-privileged users have local, terminal-server, or RDP access, as exploitation requires local execution. Given high attack complexity, no public PoC, and low EPSS, patching within your normal update cycle is reasonable, but do not defer indefinitely.

Affected
Microsoft Windows Ancillary Function Driver for WinSock (AFD, afd.sys)
Estimated exposure
mass≈1 billion+ Windows installations (AFD is a core in-box driver on all Windows systems) — The AFD driver ships in-box with every Windows installation and Windows' global installed base exceeds a billion devices, so effectively all Windows endpoints and servers are potentially affected, though only those on the versions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.